Group Policy Loopback Processing Not Working


hello,

i having issues applying gp loopback policy terminal server. have performed following steps create loopback policy:

  1. created new ou ts
  2. added ts ou , linked gpo
  3. added authenticated users, computer, , terminal server user group security filtering
  4. delegation set authenticated users - read(from security filtering),domain admins - custom, enterprise admins - custom, enterprise domain controllers - custom, ts computer - read (from security filtering), system -custom, terminal server users read (from security filtering)
  5. enabled user gpo processing mode under computer configuration

i noticed when run gpresult on target computer following message:

rsop data domain\administrator on domain-termsvr : logging mode

--------------------------------------------------------------------

os type: microsoft(r) windows(r) server 2003 standard x64 ed

ition

os configuration: member server

os version: 5.2.3790

terminal server mode: application server

site name: default-first-site-name

roaming profile:

local profile: c:\documents , settings\administrator.domain

connected on slow link?: no

computer settings

------------------

cn=domain-termsvr,ou=terminal server,dc=domain,dc=local

last time group policy applied: 1/25/2012 @ 8:57:51 am

group policy applied from: domain-dca.domain.local

group policy slow link threshold: 500 kbps

domain name: domain

domain type: windows 2000

applied group policy objects

-----------------------------

password complexity

printers

default domain policy

local group policy

the following gpos not applied because filtered out

-------------------------------------------------------------------

loopback policy

filtering: denied (security)

i drive map

filtering: not applied (empty)

the computer part of following security groups

-------------------------------------------------------

builtin\administrators

everyone

builtin\users

remote desktop users

nt authority\network

nt authority\authenticated users

this organization

domain-termsvr$

terminal server users

domain computers

user settings

--------------

cn=administrator,cn=users,dc=domain,dc=local

last time group policy applied: 1/25/2012 @ 8:57:51 am

group policy applied from: domain-dca.domain.local

group policy slow link threshold: 500 kbps

domain name: domain

domain type: windows 2000

applied group policy objects

-----------------------------

drive map

default domain policy

the following gpos not applied because filtered out

-------------------------------------------------------------------

password complexity

filtering: not applied (empty)

local group policy

filtering: not applied (empty)

printers

filtering: not applied (empty)

the user part of following security groups

---------------------------------------------------

domain users

everyone

builtin\users

builtin\administrators

remote interactive logon

nt authority\interactive

nt authority\authenticated users

this organization

local

distribution list editors

non archived users

gfi administrators

domain admins

samba admins

global_conf

group policy creator owners

finance

enterprise admins

exchange view-only administrators

exchange public folder administrators

exchange recipient administrators

exchange organization administrators

schema admins

as can see computer loopback policy filtering denied. not sure how fix seems though have permissions set correctly. appreciated. thanks.

 


it looks @ though there sort of issue original gpo policy. created test loopback gpo , work fine. removed security settings on original gpo , set default security settings back. thing noticed did not have have computer account listed in security filtering or delegation tab. seems though after removed started working. group in security filtering , delegation authenticated users. there other default groups domain admins , enterprise admins listed in delegation tab well. hope someone. help.


Windows Server  >  Group Policy



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client